Resources, Roles, Responsibility and Authority
Introduction
Security operations depend on more than boots on the ground. Effective service delivery under ISO 18788:2015 requires that organizations define and allocate the right resources, roles, responsibilities, and authorities across all levels of the Security Operations Management System (SOMS).
Clause 8.6 emphasizes that for a SOMS to be credible, it must not only exist on paper but also demonstrate that people, processes, and tools are empowered, accountable, and adequately resourced.
1. Resources
Security providers must identify and allocate all resources necessary to achieve strategic, tactical, and operational objectives. These include:
- Human Resources: Trained guards, supervisors, managers, specialists (legal, HR, compliance).
- Facilities and Infrastructure: Control rooms, offices, armouries, accommodation for deployed staff.
- Equipment and Technology: Radios, mobile phones, satellite systems, CCTV, drones, biometric access controls.
- Transport Assets: Vehicles, motorcycles, bicycles for patrols and rapid response.
- Financial Resources: Budgets for operations, training, maintenance, and compliance programs.
- Training and Development: Continuous training aligned with ISO 10015 and skills gap assessments.
- Information Systems: Secure platforms for reporting, incident logging, risk registers, and document control.
Key Point: Resources must be fit-for-purpose, documented, and auditable to show readiness and sustainability.
2. Roles
ISO 18788 requires that organizations define roles clearly across the hierarchy of security operations:
- Strategic Roles:
- Board and Executive Committee - define vision, approve policies, allocate resources.
- Tactical Roles:
- Divisional and Regional Managers - translate strategy into operational directives.
- Operational Roles:
- Supervisors and Security Personnel - execute tasks, apply SOPs, and report incidents.
Each role must be linked to job descriptions, aligned with job grading methodologies such as Paterson or Hay, ensuring that responsibilities match qualifications and competence.
3. Responsibilities
Responsibilities must be allocated in a way that ensures accountability without overlap or ambiguity:
- Top Management: Demonstrate leadership and commitment (Clause 5).
- Managers: Ensure SOP implementation, monitor KPIs, and enforce policies.
- Supervisors: Oversee compliance with Rules of Engagement (RoE), Use of Force Continuum, and incident reporting.
- Personnel: Carry out daily duties in compliance with policies, codes of conduct, and human rights obligations.
- Compliance Officers: Ensure conformity with VPSHR, ISO standards, and local laws.
- Support Staff (HR, Finance, Logistics): Provide operational sustainability.
Responsibilities must also extend to grievance handling, whistleblowing processes, and corrective action implementation.
4. Authority
Authority must be clearly defined and communicated, ensuring personnel know the extent and limits of their powers:
- Operational Authority: Supervisors may authorize routine searches or incident escalation.
- Tactical Authority: Managers may authorize deployment of additional resources or emergency response plans.
- Strategic Authority: Executives authorize policy changes, resource allocation, and external engagements.
Authority must be documented in governance records, with sign-off matrices showing who can authorize:
- Weapons issuance.
- Apprehension or detention.
- Deployment of armed personnel.
- Emergency responses.
This prevents unauthorized actions and ensures accountability during audits.
Integration with Other ISO 18788 Clauses
- Clause 5 (Leadership and Commitment): Resources and roles reflect tone at the top.
- Clause 7 (Support): Resources link directly to competence, awareness, and documented information.
- Clause 8.3 (Use of Force): Roles and responsibilities define authorization to carry weapons or apply force.
- Clause 9 (Performance Evaluation): Responsibility for monitoring and measuring SOMS effectiveness.
- Clause 10 (Improvement): Authority to implement corrective and preventive actions.
Documentation and Audit Evidence
Auditors will expect:
- Organizational Structure Charts - Showing reporting lines and accountability.
- Job Descriptions - With roles, responsibilities, and required competencies.
- Responsibility & Authority Matrix - Defining sign-off powers at strategic, tactical, and operational levels.
- Resource Registers - Documenting available personnel, equipment, and facilities.
- Training and Competence Records - Linked to roles and responsibilities.
- Audit Reports - Evidence of compliance reviews on role clarity and resource adequacy.
Conclusion
Clause 8.6 ensures that security companies demonstrate not only intent but capacity. By allocating the right resources, defining clear roles, assigning responsibilities, and clarifying authority, organizations create a SOMS that is effective, auditable, and trusted by clients, regulators, and communities.
This clarity eliminates ambiguity, strengthens accountability, and ensures that strategic objectives cascade down into tactical and operational actions, supported by the right people and resources at the right time.